Privacy Policy Template

The service

What and why

The notice

Sections
8
in reading order
Checks
9
Switches on
0
Who is responsible
(the operator) is responsible for the personal data described in this notice.

What we collect
(list the categories of personal data collected — account details, usage data, payment records, and so on.)

Why we collect it
(one purpose per line: provide the service, take payment, prevent fraud, send updates.)

Our legal basis
We rely on the performance of our contract with you for the data needed to run (the service), on your consent for marketing and optional features, and on our legitimate interests for security and service improvement. Where consent is the basis, you can withdraw it at any time without affecting what was already done lawfully.

Who we share it with
(name the processors and recipients — hosting, payments, analytics, support — or state plainly that personal data is not sold or shared.)

How long we keep it
(state a retention period for each category, or the rule that decides it.)

Your rights
You can ask for a copy of your personal data, ask for it to be corrected or deleted, ask for it in a portable format, object to processing based on legitimate interests, and withdraw consent for marketing. Requests go to (the contact address) and are answered within the period the law allows. You also have the right to complain to your data-protection authority.

Changes to this notice
This notice may change. A material change will be announced before it takes effect.

Checks

  • No service named; a notice has to say what it covers.

  • No operator named; a reader has to know who is responsible for the data.

  • No contact address; rights requests need somewhere to arrive.

  • No jurisdiction; the law that applies decides what the notice must contain.

  • No effective date; readers and archives both need the version marker.

  • No data categories listed; a notice that does not say what it collects cannot be meaningful.

  • No purposes stated; collection without a named purpose is the finding regulators look for first.

  • No retention period; indefinite storage is the second thing a reader checks.

  • No recipients named; name the processors and recipients, or state plainly that personal data is not sold or shared.

Scope and limits

The sections follow the published shape of a privacy notice: who is responsible, what is collected, why, on what basis, who it is shared with, cookies, retention, rights, transfers, marketing, children, automated decisions, changes and contact.

This is a drafting template, not legal advice. Data-protection law differs by jurisdiction, and the rights, transfers and children's sections in particular should be reviewed by a qualified adviser before publication.

The privacy policy template assembles the sections a data-protection notice is read for and checks the pairings that make one complete: collection with purposes, purposes with a retention period, sharing with named recipients.

What is Privacy Policy Template?

The privacy policy template assembles a notice in the published order: who is responsible, what is collected, why, on what legal basis, who it is shared with, cookies, how long it is kept, your rights, transfers, marketing, children, automated decisions, changes and contact. Each section is built from your parameters, and the switches add the sections a service actually needs so the notice stays proportionate to what the product does.

The checks catch the pairings that make a notice incomplete in practice. Data categories with no purposes is the first: collecting personal data without naming why is the finding a regulator looks for, and a reader cannot judge a collection they cannot connect to a reason. Purposes with no retention period is the second, because indefinite storage is the thing readers check after they check what is collected. Sharing with no named recipients is the third — the section has to list processors and recipients, or state plainly that personal data is not sold or shared. Transfers without a home jurisdiction, cookies described without cookie data among the categories, and children's data without a minimum age close the set.

The rights section is always present, because it is the part a reader actually uses. It covers access, correction, deletion, portability, objection to processing based on legitimate interests, and withdrawal of consent, and it names the contact where requests arrive. The legal basis section follows the standard three: performance of a contract for the data needed to run the service, consent for marketing and optional features, and legitimate interests for security and improvement.

The switches are deliberate. Cookies, international transfers, marketing, children's data and automated decisions are each off by default, because a notice that claims more than the service does is as wrong as one that claims less. Turning marketing on adds the opt-out language; turning children's data on adds the minimum-age field and the check that demands it be filled.

The notice is a document rather than a page: copyable and downloadable as plain text, with the sections in the order a reader moves through them. The effective date and the changes section sit at the end, which is where a returning reader looks for what changed.

What the template cannot do is practise data-protection law. The rules differ by jurisdiction, mandatory wording varies, and the transfers, rights and children's sections are the ones a qualified adviser should review before publication. Treat the page as a first draft that has already asked the obvious questions and answered none of them incorrectly.

Write the notice from the product, not from a template library. The categories, purposes and recipients sections are facts about the service, and the exercise of filling them in is itself a check on how much data the product actually collects. Teams routinely discover a tracking script or an export nobody remembered; better in the draft than in a request.

Keep the effective date and a short history. When a reader asks what changed, a dated version list answers in one line; the changes section is otherwise a promise without evidence. A previous version kept on file is also the quickest way to answer a complaint about consent given under older wording.

How to use Privacy Policy Template

  1. Name the service, the operator, the contact and the jurisdiction.
  2. List the data categories collected and one purpose for each.
  3. Set the retention period and name the recipients or processors.
  4. Turn on the switches the service needs — cookies, transfers, marketing, children, automated decisions.
  5. Clear the checks, then have the draft reviewed before publication.

When to use Privacy Policy Template vs related tools

Use the privacy policy template when a consumer-facing service needs a notice and the structure has to be right before the wording is: a new app, a subscription product, a site that has started collecting more than it used to. It is most useful before a lawyer sees the document, because the missing pairings do not need legal judgement to fix. The commercial counterpart is the Terms of Service Template, which shares the operator, contact and jurisdiction facts. The notices a policy change generates go out through the Email Template Library, and the questions readers ask about data show up in the FAQ Generator.

Privacy & Security

This tool runs entirely in your browser — no data ever leaves your device. There is no server round-trip, no upload, no logging, and no account required. Your input is processed locally using client-side JavaScript and is never stored, transmitted, or accessible to anyone else. When you close the tab, everything disappears.

Frequently asked questions about Privacy Policy Template